Have I Been Pwned: hackers stole 71K+ Nvidia staff credentials, including email IDs and Windows password hashes, many of which were “cracked and circulated”
The ransomware group that claims to have taken a terabyte of data from chipmaking giant Nvidia is threatening to release the company's …
Context & Ripple Effects
Nvidia first described internal outages as an incident, then confirmed that employee data and proprietary information had leaked in the claimed 1TB theft. The newly identified credential set makes the employee-facing exposure of that earlier confirmed leak more concrete.
The breach was already escalating beyond data disclosure: researchers later reported that leaked Nvidia code-signing certificates were being used to sign Windows malware and hacking tools. Together, the reports show stolen material being turned into operational access and weaponization.
First-order effects
- Nvidia employees whose Windows password hashes were cracked and circulated face immediate exposure wherever those passwords or related account credentials are still in use, forcing Nvidia to prioritize credential resets and account protection.
- Nvidia's security response now has to address both the disclosed employee records and the misuse of leaked code-signing certificates against Windows users.
Second-order effects
- Windows security teams and Nvidia customers must treat software signed with the exposed certificates as a potential delivery path for malware, widening the incident beyond Nvidia's own network.
- The credential disclosure gives the Lapsus$ pressure campaign additional leverage alongside its threat to release stolen source code unless Nvidia changes GPU mining limits and driver licensing.
Third-order effects
- The incident illustrates how a single corporate intrusion can combine workforce identity data, proprietary code, and signing infrastructure into separate attack paths, raising the value of protecting identity and software-release systems together.
- If this pattern persists, major technology vendors will be judged not only on whether they contain a breach, but on how quickly they revoke or replace assets that attackers can reuse outside the company.
The trend: High-value corporate breaches are increasingly becoming multi-stage campaigns in which stolen employee credentials and software-trust assets extend the damage beyond the initial data theft.